Closed Bug 272249 Opened 20 years ago Closed 18 years ago

LXR error reveals server configurations and versions

Categories

(Webtools Graveyard :: MXR, defect)

x86
Windows 2000
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: bulk88, Assigned: bear)

References

()

Details

User-Agent:       Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Build Identifier: 

Went to thios page, got an error. It reveals under the hood stuff about the 
site, and what perl version is runs. The version (5.6.x) seems old to me (maybe 
b/c I am a newbie), so it could be a security risk.

Reproducible: Always
Steps to Reproduce:
1. goto http://lxr.mozilla.org/seamonkey/ident?i=this 
2.
3.
This is not a bug. I'm quite sure that the server intentionally advertises this
information. 

-> Myk.
Assignee: mitchell → myk
Component: Miscellaneous → Server Operations
Confirming the error message. Not sure this is serious problem requiring the
confidential flags, but switching from the general security flag to the more
appropriate webtools security flag.
Group: security → webtools-security
Status: UNCONFIRMED → NEW
Ever confirmed: true
Summary: reveals server configurations and versions → LXR error reveals server configurations and versions
It's common knowledge that we run RHEL, and those are the standard paths for
those files on RHEL, so it's not exposing any information anyone wouldn't know
anyway.

That said, I'm not a big fan of the whole "security by obscurity" thing, we're
better off making sure the system can't be broken into for them to have the
chance to use it.
Assignee: myk → leaf
Component: Server Operations → LXR
Product: mozilla.org → Webtools
QA Contact: mitchell → timeless
(moved to LXR because the fact those error messages are showing up is an LXR bug)
QA Contact: timeless → lxr
I don't see anything server-related when I go to http://lxr.mozilla.org/seamonkey/ident?i=this

Is this still an issue?
Assignee: leaf → bear
This error isn't showing up any more, and this isn't really a security issue. Closing out.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → WORKSFORME
Group: webtools-security
Group: webtools-security
Group: webtools-security
Group: webtools-security
Group: webtools-security
Group: webtools-security
Group: webtools-security
Product: Webtools → Webtools Graveyard
You need to log in before you can comment on or make changes to this bug.